Quick Start
Step 1: Enable Console Access
-
Sign in to the Sumo Logic CIP console to create a new user.
-
Navigate to Administration > Users and Roles > Users and click the Add User button at the top right of the page.
-
Fill in the below information.
-
For First Name, type Expel.
-
For Last Name, type SOC analysts.
-
For Email, type soc+<your_company_name>@expel.io.
Note
Yes, the "+" sign is part of the email address, and it's important. Click here to find out why. -
For Assigned Roles select the Analyst role.
-
Click Add New User.
-
-
Verify that Expel SOC now appears on the Users page.
-
Sign into Sumo Logic Cloud SIEM Enterprise console.
-
Navigate to Accounts.
-
Click Invite at the top right of the page.
-
Invite the Sumo Logic CIP user from step 1 with a role of Analyst.
Step 2: Generate API Credentials
-
Edit the Sumo Logic Cloud SIEM Enterprise user created in Step 1.
-
Select API Key Enabled.
-
Select YES, REGENERATE API KEY.
-
Click UPDATE and log out.
-
Log back into Sumo Logic Cloud SIEM Enterprise console with the new user created in Step 1.
-
Click the user profile at the top right of the page.
-
Copy API Key and make note of it.
Step 3: Configure the Technology in Workbench
-
In the side menu, navigate to Organization Settings > Security Devices.
-
Select Add Security Device.
-
Sn the search box, type "Sumo Logic" for and select Sumo Logic Cloud SIEM Enterprise (formerly JASK).
-
A configuration pane displays. Complete the fields as follows:
- Name - enter a name that might help you more easily identify this integration, such as “CompanyName Sumo Cloud SIEM Enterprise”; this name will display in Workbench under the Name column, and is a text string that you can filter on.
- Location - enter the location of your integration, for example, “cloud.” This is also a text string that you can filter on, so we recommend being consistent with location naming across your Expel integrations.
- Username - enter the username used to authenticate to the device.
- Password - enter the password used to authenticate to the device.
-
Server address - provide the Sumo Logic Cloud SIEM Enterprise URL.
-
Sumologic query indices - leave this field blank.
- Select Save.